CVE-1999-0872

CVSS 2.0 Score 7.2 of 10 (high)

Details

Published Aug 25, 1999
Updated: Nov 20, 2024

Summary

CVE-1999-0872 is a significant vulnerability affecting the Vixie cron daemon. This issue permits local users to exploit a buffer overflow weakness in the software's handling of overly long MAILTO environment variables found in crontab files. Successful exploitation could result in the attacker gaining root access to the system. This vulnerability was identified in 1999 and poses a serious risk to systems using the Vixie cron implementation with unsecured crontab files. It is crucial for system administrators to apply patches or updates to mitigate this risk and restrict environment variable length to prevent potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Red Hat Enterprise Linux
  • Debian

Affected Vendors

  • Debian
  • Red Hat